The operator’s identity and privacy contact have not yet been provided. The operator needs to complete this document.
This policy describes data processed through Precauti features. Accepting the Terms is not blanket permission to process data and does not replace specific authorizations.
1. Controller and channels
Controller: [information not yet provided by the operator], [information not yet provided by the operator], [information not yet provided by the operator]. Privacy: [information not yet provided by the operator]; support: suporte@precauti.com. These channels receive data requests, questions and incident reports; they are not emergency services.
2. Account and authentication
We process account ID, name, email, phone if provided, country, language, stated gender, birth date, preferences and authentication information. Apple or Google login involves information authorized on those platforms. Device biometrics return an authentication result; the app does not receive the facial template or fingerprint used by Face ID/Touch ID.
The site creates a sign-in identity and prepares the account through the same profile service used by the app. This step does not request name, country, profile language, sex or date of birth: these are entered and confirmed in the app. The website language does not automatically confirm a profile language. Installation does not transfer the browser session. Valid referrals may be associated with account creation; trusted-contact invitations require a complete profile and permission confirmation in the app.
3. Location and participants
The map uses location when permitted. Activated SOS or route-follow sessions send position, time, identity and session status to infrastructure and authorized participants. With permission and an active session, updates may continue while minimized or with the screen locked; the system can limit them. End the session and adjust permissions to stop new access as the feature allows. Map and geocoding providers may receive coordinates and technical information needed for requests.
4. Recordings and records
Vault, SOS, reports and support may receive audio, photos, videos, text, times and metadata. Enabled SOS audio may continue in an active session with the screen locked and upload in fragments; failed transfers can leave local recovery files. Vault content is not automatically published to the map. Exporting or sharing creates a copy under the chosen recipient’s control. Violence-related content can reveal specially protected information; avoid excessive third-party data.
5. Purchases and benefits
We process products, transaction IDs and technical receipts, subscription status, cancellations, discounts, credits and reversals to validate access. Card details used at checkout are handled by the store and are not requested by this app flow. Commission or delivery programs may require identity, payment keys, delivery addresses and receipts. Do not place this information in public reports.
6. Searches and sources
We process queries, results, sources, statuses and times to display and recover preventive searches and prevent abuse. Enabled sources receive necessary search criteria. The DataJud implementation searches case numbers in enabled courts and does not provide access to sealed proceedings. Publicly accessible data is also legally protected. Results and identifiers remain linked to the account with restricted access.
7. Technical data and support
Servers and security mechanisms may process IP addresses, app versions, device information, notification tokens, integrity checks, operational events and support messages to provide the service and control access. Separately, you can enable optional technical diagnostics in Original settings. Diagnostics send error types/codes, code locations, model/manufacturer, OS, app version/build, language, total memory and screen characteristics when available, local time, UTC offset, the time-zone name provided by the system and server receipt time. A random installation identifier is linked to the account to deduplicate records and compare participating installations; it is not an IMEI or serial number. This collection does not send free-form exception messages, passwords, location, audio, screen contents or the device’s personal name. Correlations help investigate failures by model/version and do not represent all devices in the market. In Admin, technical diagnostics from approved administrative users support operational reliability and security, with access restricted to authorized staff.
8. Purposes and legal bases
Account operation, requested features and subscription validation may rely on contract performance. Legal obligations and legal claims justify specific processing. Security may rely on legitimate interests following assessment of necessity and rights. Optional features and sensitive data require their own legal basis and, where applicable, specific consent. Protection of life is not general permission for permanent monitoring. Accepting this policy does not authorize every legal basis at once.
9. Recipients
Recipients may include chosen participants, audiences of published features, authorized staff, Google/Firebase/Google Cloud, Apple, map providers, search sources, email and necessary delivery/payment services. We share information relevant to each purpose and recipient’s role. Authorities receive data with a legal basis and appropriate process; SOS is not automatically forwarded to police.
10. Marketing and choices
Referral codes and campaign parameters may identify registration and benefit sources. Camera, microphone and location permissions do not authorize behavioral advertising. Private evidence and location sessions are not offered for advertising. Future advertising or cross-service tracking requires assessment, disclosure and separate choices where applicable. Marketing email or push must allow refusal, separately from necessary operational communications.
11. Retention and deletion
Account data and content are retained as needed for the feature or until applicable deletion. Preventive searches and optional diagnostics follow a 30-day technical policy with scheduled batch removal, subject to execution cycles and failure recovery; removal is not instantaneous. The local diagnostic queue holds at most 30 events for seven days, stops when sending is disabled and is separated by account. The diagnostic preference remains as needed for the account. Data-access response drafts expire after one hour; published pages become part of the request history. Privacy requests are retained for handling and removed through account deletion, subject to necessary administrative evidence. Incident, financial and audit records follow necessity assessment, legal duties and evidence preservation; audit purge requires a configured policy and respects legal holds. Backups and providers may have separate cycles; justified retention must be explained to the account owner.
12. Rights and requests
Request confirmation, access, correction, sharing information, deletion and, where applicable, portability, objection, restriction and review of automated decisions through Privacy and diagnostics in settings or [information not yet provided by the operator]. The center lets you follow up, add information, cancel requests and receive responses; cancelling a request does not automatically delete the account. Staff may request proportionate proof of identity and scope without asking for passwords. The displayed target is a service estimate and does not replace applicable legal deadlines. Automatically prepared data pages identify their scope and may require other sources, attachments and review of third-party rights. You may withdraw optional diagnostic consent at any time: collection stops on this device even offline, and the preference syncs later. Withdrawal does not invalidate previous lawful processing or disable records essential for security and service delivery.
13. International transfers
Global infrastructure may process data outside Brazil or your country. The controller must disclose relevant destinations, suppliers and safeguards and make information about the transfer mechanism available. Providing the service does not amount to blanket transfer consent. Transfers covered by LGPD, GDPR or other laws require an appropriate basis and safeguards; contact the privacy channel for details.
14. Minors
The service is not intended for children under 13. Processing children’s and adolescents’ data must respect their best interests and country-specific representation or consent requirements. Guardians may request explanations and removal. Do not request or submit unnecessary data about minors; access and processing must be reviewed when no appropriate basis exists.
15. Security and incidents
We use authentication, access rules, specific permissions, transport/storage protection and administrative traceability. Diagnostics and requests are accessed through authenticated services; account owners receive only their own requests and responses. Internal notes and incident records are restricted to authorized staff. No protection eliminates all risks. Report concerns to [information not yet provided by the operator]; recording an incident in Admin does not automatically notify authorities or replace the controller’s assessment. Legally required communications to affected people and authorities follow the risks, facts, deadlines and applicable rules.
16. Choices, regional rights and revisions
Denying permission can reduce the related feature; it is not consent for another purpose. Account deletion and subscription cancellation are separate processes. Where GDPR/UK GDPR or state privacy rights apply, additional mandatory rights remain protected without discrimination for lawful exercise. Policy changes carry a version and date; new optional purposes require separate handling.